RFI Flashcards
DREAD
Quantifying risk by threat
Integrity protection encompasses…
more than just data. Also OS, apps, HW
DREAD + STRIDE
Threat modeling techniques
Categories of security investigations (3)
Public, Private, Individual
Linux file system that supports journaling
EXT4
Journaling file system consequence
Burns out hard drive easier
Each process starts with…
Single threat that can create more threads
A Windows job is…
A group of processes
Is a Signature ID an artifact of IPS/IDS events?
Yes
Netflow templates provide
backward compatibility on netflow supporting systems
IPFIX uses which protocol
SCTP
SILK, ELK, Graylog
Can be used for Netflow analysis
Netflow cache types (3)
Normal, Immediate, permanent
IPFIX based on which version of netflow
9
Incident Prioritization part of which phase of IR process
Detection + Analysis